import assert from "node:assert/strict"; import { readFileSync } from "node:fs"; import test from "node:test"; const migration = readFileSync( new URL("../supabase/migrations/20260904010000_read_report_candidate_range.sql", import.meta.url), "utf8", ); test("report candidate-range RPC is owner-held, service_role execute-only, and column-minimal", () => { assert.match(migration, /create or replace function public\.read_report_candidate_range\(/); assert.match(migration, /p_user_id uuid/); assert.match(migration, /p_rectification_case_id uuid default null/); assert.match(migration, /security definer/); assert.match(migration, /set search_path = ''/); assert.match(migration, /revoke all on function public\.read_report_candidate_range\(uuid, uuid\)/); assert.match(migration, /from public, anon, authenticated/); assert.match(migration, /grant execute on function public\.read_report_candidate_range\(uuid, uuid\)\s+to service_role/); assert.match(migration, /status in \('confirmed', 'completed'\)/); assert.match(migration, /status = 'candidate_accepted'/); assert.match(migration, /jsonb_build_object\('start_time', v_start, 'end_time', v_end\)/); assert.doesNotMatch(migration, /grant\s+(all|select|insert|update|delete)\s+on table public\.agentic_rectification_cases/i); assert.doesNotMatch(migration, /alter table/); assert.doesNotMatch(migration, /enable row level security|create policy/i); });